Here is a conversation that happens in startup circles more often than it should.
A founder reads about the DPDP Act. They get to the part about appointing a Data Protection Officer. They panic slightly, calculate what a senior privacy professional costs, decide they cannot afford one, and put the whole compliance question aside for later.
Later never comes.
What they missed, because almost nobody talks about it, is that the Data Protection Officer requirement under the DPDP Act almost certainly does not apply to them. What does apply to them, immediately and without exception, is the grievance officer requirement. And a grievance officer costs nothing to appoint, takes less than a day to set up, and is one of the simplest compliance steps in the entire Act.
This post untangles the confusion between these two roles, tells you exactly who needs what, and shows you how to implement the one you actually need before you finish reading.
Where the confusion comes from
The Data Protection Officer is a concept most people have encountered through GDPR, the European Union’s data protection regulation. Under GDPR, certain organisations must appoint a DPO: a senior professional with expert knowledge of data protection law, responsible for monitoring compliance, training staff, and acting as the point of contact between the organisation and the supervisory authority.
When the DPDP Act came into force in India, commentators, many of them drawing on GDPR expertise, began writing about the DPO requirement in the Indian context. Founders read these pieces and assumed the same requirement applied to them.
It does not. At least not yet, and not to most startups.
Here is the actual position under Indian law.
The Data Protection Officer — who actually needs one
Under Section 10 of the DPDP Act, the Data Protection Officer requirement applies only to Significant Data Fiduciaries.
A Significant Data Fiduciary is an entity that the Central Government notifies as such, based on factors including the volume and sensitivity of data processed, the risk to the rights of data principals, national security considerations, and the potential impact on sovereignty and public order.
As of now, the Central Government has not notified any entity as a Significant Data Fiduciary. The list has not been published. Until it is and until your startup appears on it, the DPO requirement does not apply to you.
Even when the list is published, it is almost certain to include large technology platforms, major social media companies, and entities processing sensitive data at significant scale. A seed-stage SaaS startup with ten thousand users is not going to be on that list anytime soon.
The DPO under the DPDP Act must be based in India, must be an employee of the data fiduciary, and must be accountable to the board of directors. This is a senior, full-time role. It is designed for organisations with mature, large-scale data operations — not for early-stage startups.
If you are a startup that is not a Significant Data Fiduciary, you do not need a DPO right now. Watch for government notifications. Build your compliance foundations. But do not let the DPO question paralyse you when there is a simpler, more immediate obligation waiting to be fulfilled.
The Grievance Officer — who needs one and when
Under Section 8(8) of the DPDP Act, every data fiduciary, without exception, without a size threshold, without a notification requirement, must publish the name and contact details of a person who can be contacted by data principals for grievance redressal.
This person is the Grievance Officer.
Every startup that collects personal data from Indian users is a data fiduciary. Every data fiduciary must have a Grievance Officer. There is no carve-out for small companies. There is no minimum user threshold. If you have one user whose data you process, the obligation exists.
The Grievance Officer’s role is straightforward. When a user has a complaint — their data was used for a purpose they did not consent to, their erasure request was ignored, they cannot access what data you hold about them — they contact the Grievance Officer. The Grievance Officer is responsible for acknowledging the complaint and attempting to resolve it before the user escalates to the Data Protection Board.
Under the draft DPDP Rules 2025, the Grievance Officer must acknowledge a complaint within 48 hours and resolve it within 30 days. These timelines are specific. They create accountability.
Who can be the Grievance Officer? Under the current framework, there is no requirement that the Grievance Officer be a lawyer, a privacy professional, or a senior employee. For most early-stage startups, the founder or a co-founder serves as the Grievance Officer. What matters is that the role is designated, the person is reachable, and their details are publicly available.
DPO vs Grievance Officer
The Data Protection Officer is required only for Significant Data Fiduciaries notified by the Central Government. The Grievance Officer is required for every data fiduciary without exception.
The DPO must be a senior employee with expert knowledge of data protection law, accountable to the board. The Grievance Officer can be any designated person, including the founder.
The DPO’s function is internal compliance monitoring, staff training, and regulatory liaison. The Grievance Officer’s function is handling user complaints about data rights.
The DPO is a full time role at a large organisation. The Grievance Officer is a designated responsibility that at an early stage takes minimal time, most startups will receive very few formal complaints initially.
The DPO has not been triggered yet for any Indian entity. The Grievance Officer obligation is in force now, today, for every startup collecting personal data.
How to set up your Grievance Officer in a day
This is genuinely simple. Here are the four things you need to do.
Step one — Designate the person. Decide who your Grievance Officer is. For most early-stage startups, this is the founder. If you have a co-founder who handles operations or legal matters, it can be them. Write it down internally, in a board resolution if you have one, or in a simple internal document if you don’t.
Step two — Create a dedicated email address. Create an email address specifically for grievances, something like grievance@yourcompany.com or privacy@yourcompany.com. This is not strictly required by the Act but it signals professionalism, makes complaints easy to track, and ensures nothing gets lost in a general inbox. Takes five minutes to set up through your email provider.
Step three — Publish the details on your website. This is the part the Act explicitly requires. On your Privacy Policy page and on your Contact page, add a section that reads something like this:
Grievance Officer
Name: [Full name] Designation: [Founder / Co-founder / Privacy Officer]
Email: grievance@yourcompany.com
Response time: We will acknowledge your complaint within 48 hours and aim to resolve it within 30 days.
If you are not satisfied with the resolution, you may escalate your complaint to the Data Protection Board of India.
That is the entire public-facing requirement. Name, designation, email address, and a response commitment.
Step four — Set up a simple response system. Create a folder in your email for grievance complaints. When a complaint comes in, acknowledge it within 48 hours, even if you have not resolved it yet. Keep a log of complaints received, acknowledged, and resolved. A simple spreadsheet is sufficient. This log will matter if the Data Protection Board ever investigates a complaint against you.
Total time to complete all four steps: two to three hours on a Saturday morning.
One thing that trips founders up
Some founders publish a grievance officer name and email on their website and consider the matter closed. It is not.
The obligation is not merely to publish the details, it is to actually respond to complaints within the timeframe. A grievance officer who cannot be reached, who does not acknowledge complaints, or who ignores escalations is a compliance risk, not a compliance solution.
Set a calendar reminder to check the grievance inbox once a week. For most early-stage startups, you will receive no complaints for months. But the system needs to be functional before the first complaint arrives, not after.
What you should now have
After this post, you have a clear picture of the two roles and what they require. You do not need a Data Protection Officer today. You do need a Grievance Officer today and you can have one set up before this time tomorrow.
If you have already read the first two posts in this series, on what the DPDP Act requires and on the difference between a privacy policy and a consent notice, you now have the three most immediately actionable compliance steps covered. A proper consent notice. A compliant privacy policy. And a functioning grievance mechanism.
These three things will not make your startup fully DPDP compliant. Full compliance is a deeper exercise. But they are the foundation and they are what the Data Protection Board will look for first if a complaint is ever filed against you.
Start with these. Build from here.
The author is a law student specialising in tech law and data privacy. This post is for informational purposes only and does not constitute legal advice.
Leave a Reply